Rina Steenkamp - Privacy and technology
Chapter IV Controller and processor
1. Each controller and processor shall maintain regularly updated documentation necessary to fulfill the requirements laid down in this Regulation.
2. In addition, each controller and processor shall maintain documentation of the following information:
3. (deleted)
4. (deleted)
5. (deleted)
6. (deleted)
[Source: October 2013]
(65) In order to be able to demonstrate compliance with this Regulation, the controller or processor should maintain the documentation necessary in order to fulfill the requirements laid down in this Regulation. Each controller and processor should be obliged to co-operate with the supervisory authority and make this documentation, on request, available to it, so that it might serve for evaluating the compliance with this Regulation. However, equal emphasis and significance should be placed on good practice and compliance and not just the completion of documentation.
[Source: October 2013 | Notes: Recitals | Context: Recitals]
Article 28 introduces the obligation for controllers and processors to maintain documentation of the processing operations under their responsibility, instead of a general notification to the supervisory authority required by Articles 18(1) and 19 of Directive 95/46/EC.
[Source: January 2012 | Context: Proposal from the European Commission]
1. Each controller and processor and, if any, the controller's representative, shall maintain documentation of all processing operations under its responsibility.
2. The documentation shall contain at least the following information:
3. The controller and the processor and, if any, the controller's representative, shall make the documentation available, on request, to the supervisory authority.
4. The obligations referred to in paragraphs 1 and 2 shall not apply to the following controllers and processors:
5. The Commission shall be empowered to adopt delegated acts in accordance with Article 86 for the purpose of further specifying the criteria and requirements for the documentation referred to in paragraph 1, to take account of in particular the responsibilities of the controller and the processor and, if any, the controller's representative.
6. The Commission may lay down standard forms for the documentation referred to in paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 87(2).
[Source: January 2012 | Context: Proposal from the European Commission]
(65) In order to demonstrate compliance with this Regulation, the controller or processor should document each processing operation. Each controller and processor should be obliged to co-operate with the supervisory authority and make this documentation, on request, available to it, so that it might serve for monitoring those processing operations.
[Source: January 2012 | Notes: Recitals | Context: Proposal from the European Commission, Recitals]